UDM Pro guest portal setup
The UDM Pro runs UniFi OS, and UniFi OS changes three things a portal integration depends on: the login endpoint, a path prefix in front of every Network call, and a CSRF token that has to come back on each request. The integration handles all three; your job is the hotspot settings and reachability.
www.voqadowifi.com, and add www.voqadowifi.com and voqadowifi.com to Pre-Authorization Access. Create a local admin without two factor, make the console reachable over HTTPS, then save its address, the site (usually default) and that login in the dashboard.At a glance
- Runs
- UniFi OS
- Address for the dashboard
- HTTPS on 443, no port
- Login the integration uses
/api/auth/login- Network API prefix
/proxy/network- Usual site id
default- Guest lands on
https://www.voqadowifi.com/guest/s/default/
Checked against the VoqadoWiFi integration code on 7 October 2026. Controller menu labels move between firmware releases; the setting names above are the ones the setup wizard prints.
Step by step
- Enable the hotspot portal on the guest SSIDIn Settings, WiFi, edit the guest SSID and turn on the hotspot or guest portal. Keep the SSID open; the portal is the gate.
- Point the external portal server at VoqadoWiFiIn the hotspot settings choose External Portal Server and enter the host
www.voqadowifi.com. UniFi always sends guests to the fixed path/guest/s/<site>/on that host, which is how VoqadoWiFi knows which venue they are at. If your Network version asks for an IP address, switch on Redirect using hostname and enter the host there instead. - Add the pre-authorization entries and leave HTTPS redirection offAdd
www.voqadowifi.comandvoqadowifi.comto Pre-Authorization Access. If your version shows an HTTPS Redirection toggle, leave it off: intercepting HTTPS is what produces certificate warnings on guest phones. - Create a local admin for the integrationUnder Admins and Users add an account restricted to local access, with access to the Network application and no two factor prompt. A ui.com cloud account cannot log in to the controller API, and a two factor challenge fails every automated login.
- Make the console reachable from the internetThe authorization call comes from VoqadoWiFi’s servers. Either forward TCP 443 to the console behind a DDNS hostname, or run an outbound tunnel to it, which also works behind carrier grade NAT.
- Save the console in the dashboard and test the connectionChoose Ubiquiti UniFi as the network vendor, enter the console’s
https://address with no port, the local admin, and leave Console Type on Auto-detect. Test Connection lists every site as id and name; click yours to fill the UniFi Site field.
What breaks on this controller
A proxy or tunnel strips the CSRF header
UniFi OS rejects state changing calls without a CSRF token, with 401 or 403. Some reverse proxies drop the x-csrf-token header. The integration falls back to the token inside the TOKEN session cookie, so a tunnelled UDM Pro still authorizes guests.
Port 8443 in the address
8443 belongs to the older self hosted controller. A UniFi OS console answers on 443. With Auto-detect, the integration probes the root of the address: a 200 means UniFi OS, a redirect to /manage means the older controller.
A ui.com account in the dashboard
Cloud accounts and accounts with two factor cannot complete an API login. Portal Health shows auth with “login rejected”. Create a local admin as in step 4.
Two venues, two consoles, one site name
Every single site console calls its site default, so two shops on separate UDMs both send guests to /guest/s/default/. Add each venue’s access point MACs to its location in the dashboard and VoqadoWiFi matches the guest to the right venue from the ap parameter.
What the integration does on every guest
It logs in at /api/auth/login on the console, reads the CSRF token from the response header or, failing that, from the TOKEN cookie, then posts authorize-guest for the guest’s MAC to /proxy/network/api/s/<site>/cmd/stamgr with a session length in minutes and the access point MAC.
Each attempt has an 8 second limit and there are two attempts. A rejected login is not retried, because a wrong password will not fix itself. A stale session is retried with a fresh login.
Questions
Does this work on the UDM SE, UDM and UDR too?
Can I use unifi.ui.com remote access as the controller address?
Do I have to type the site name?
Does guest isolation need to change?
Deeper reading
Longer articles from the blog that cover this controller. Where an article and this page disagree, this page is the one checked against the current integration.
- UDM Pro guest WiFi portal guide. The longer read on UniFi OS specifics and firmware habits.
- Exposing a UniFi controller with Cloudflare Tunnel. No port forwarding, works behind carrier grade NAT.
- Guest VLAN segmentation
Keep reading
Sources: lib/unifi/api.ts, app/guest/s/[site]/route.ts and docs/unifi-setup-guide.md, read on the date above. Ubiquiti and UniFi are trademarks of Ubiquiti Inc. VoqadoWiFi is not affiliated with or endorsed by either vendor.
Run your UniFi portal free
One location and 25 guest logins a month on the Starter plan, no card. The dashboard prints the finished portal URL for this controller.